- The Photo Gallery by 10Web WordPress plugin before 1.8.15 did not ensure that uploaded files are kept inside its uploads folder, allowing high privilege users to put images anywhere in the filesystem via a path traversal vector.
We have discovered 36,897 live websites that are affected by CVE-2023-1427.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 36,897 live websites (35.15% of Photo Gallery by 10Web install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 324 versions ( 52.68% of all versions) |
![]() | 9,188 websites |
![]() | 4,523 websites |
![]() | 2,133 websites |
![]() | 2,026 websites |
![]() | 2,018 websites |
![]() | 1,368 websites |
![]() | 1,111 websites |
![]() | 1,020 websites |
![]() | 864 websites |
![]() | 681 websites |
.com | 12,898 websites |
.de | 2,368 websites |
.org | 1,852 websites |
.ru | 1,675 websites |
.pl | 1,568 websites |
.nl | 937 websites |
.it | 881 websites |
.co.uk | 873 websites |
.net | 786 websites |
.fr | 738 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*********.kz | ![]() | **,*** | |
******.name | ![]() | **,*** | |
************.ru | ![]() | **,*** | |
***********.org | ![]() | **,*** | |
**********.**.uk | ![]() | **,*** | |
****************.org | ![]() | **,*** | |
***.***.ph | ![]() | **,*** | |
******************.org | ![]() | **,*** | |
*****.edu | ![]() | ***,*** | |
*********.net | ![]() | ***,*** |
FAQ